https://portswigger.net/daily-swig/dna-data-of-sexual-assault-victims-exposed-in-breach-at-us-laboratory The Daily Swig [ ] ( ) ( ) ( ) ( ) ( ) ( ) ( ) ( ) Regions Hacking News Data Breaches Cyber-attacks Vulnerabilities Bug Bounties More About Africa Asia Europe Middle East Latin America North America Oceania View all US news APT focus Take a closer look at Iran's state-sponsored hacking groups Regions Latest Hacking News Hacking Tools Hacking Techniques Pen Testing Cloud Security Database Security Email Security Network Security View all hacking news Hacker-powered security Human error bugs increasingly making a splash, study indicates Hacking news Latest Data Breaches Data Leak Organizations Enterprise Security View all data breach news In focus Software supply chain attacks - everything you need to know Data Breaches Latest Cyber-attacks Cybercrime Cyber Warfare DDoS Attacks Supply Chain Attacks View all cyber-attack news Special report North Korean cyber-threat groups become top-tier adversaries Cyber Attacks Latest Vulnerabilities Zero-Day News RCE XSS SQL Injection SSRF CSRF XS Leaks View all security vulnerability news What's in a (domain) name? How expired web domains are helping criminal hacking campaigns Vulnerabilities Bug Bounty News VDP News Research OSINT View all bug bounty news Bug Bounty Radar The latest programs for February 2022 Bug bounties Interviews Analysis Research Deep Dives Browsers Ransomware Phishing Malware Encryption Privacy Mobile IoT Policy and Legislation Machine learning DNS Open Source Hardware Authentication Events View all infosec industry news Cybersecurity conferences A schedule of events in 2022 and beyond More topics DNA data of sexual assault victims exposed in breach at US laboratory Emma Woollacott 25 February 2022 at 12:00 UTC Updated: 25 February 2022 at 12:04 UTC Data Breach Healthcare US Twitter WhatsApp Facebook Reddit LinkedIn Email Medical information included in leak after third-party compromise DNA data of sexual assault victims exposed in breach at US laboratory The personal data of an unknown number of victims of sexual assault has been exposed following a breach at Oklahoma-based DNA Solutions. The laboratory processed DNA evidence from rape victims, known as 'rape kits', for the Oklahoma City Police Department (OKCPD), amongst other clients, over a two-year period. The breach is said to have taken place last November. "The Oklahoma City Police Department was recently made aware that a company that had performed forensic testing for the department suffered a network security incident," captain Valerie Littlejohn of the OKCPD told The Daily Swig. "DNA Solutions Inc. determined that an unauthorized third party accessed their network and may have compromised certain sensitive personal and health related information from sexual assault kits sent to them for forensic testing." Littlejohn added that the department no longer has a contract with the company. Read more of the latest data breach news The number of people affected isn't known, but the OKCPD says it has written to everybody who supplied a rape kit to DNA Solutions at any time. DNA Solutions blames the breach on an unnamed third-party software. "On November 18, 2021, our team detected and stopped a network security incident, immediately secured the network environment, and engaged cybersecurity experts to conduct a comprehensive investigation into the extent of the unauthorized activity. "During this time, we also notified federal law enforcement about the incident," the company told The Daily Swig in a statement. "The investigation determined an unauthorized party accessed the network through an unknown vulnerability in a third-party software provider's platform and may have compromised certain personal and medical information." RECOMMENDED Red Cross servers 'were hacked via unpatched ManageEngine flaw' The data is believed to include medical information but did not, says the company, include social security numbers, driver's license information, or financial information. Nevertheless, says the company, those people potentially affected should enrol in the credit monitoring and identity protection services that it is being offered free of charge. DNA Solutions says it has also notified all those who may have been affected by the breach. "Protecting data is a responsibility we approach with the utmost seriousness, and we are committed to safeguarding against future threats," the company says. DON'T MISS Data wiper deployed in cyber-attacks targeting Ukrainian systems Data Breach Healthcare US North America Data Leak Government Database Security Network Security Vulnerabilities Privacy Hacking News Organizations Emma Woollacott Emma Woollacott @EmmaWoollacott Twitter WhatsApp Facebook Reddit LinkedIn Email This page requires JavaScript for an enhanced user experience. Latest Posts rhoToken robbery Flurry Finance heist nets crypto thieves $295k 25 February 2022 rhoToken robbery Flurry Finance heist nets crypto thieves $295k Data study reveals predictors of supply chain attacks in NPM repositories 25 February 2022 Data study reveals predictors of supply chain attacks in NPM repositories Researchers outline the six key indicators that an NPM package may be compromised Data wiper deployed in attacks targeting Ukrainian systems 24 February 2022 Data wiper deployed in attacks targeting Ukrainian systems Newly named 'HermeticWiper' malware discovered on hundreds of endpoints Related stories This page requires JavaScript for an enhanced user experience. rhoToken robbery Flurry Finance heist nets crypto thieves $295k 25 February 2022 rhoToken robbery Flurry Finance heist nets crypto thieves $295k Data study reveals predictors of supply chain attacks in NPM repositories 25 February 2022 Data study reveals predictors of supply chain attacks in NPM repositories Researchers outline the six key indicators that an NPM package may be compromised DNA data of sexual assault victims exposed in breach at US laboratory 25 February 2022 DNA data of sexual assault victims exposed in breach at US laboratory Medical information included in leak after third-party compromise Data wiper deployed in attacks targeting Ukrainian systems 24 February 2022 Data wiper deployed in attacks targeting Ukrainian systems Newly named 'HermeticWiper' malware discovered on hundreds of endpoints Burp Suite Web vulnerability scanner Burp Suite Editions Release Notes Vulnerabilities Cross-site scripting (XSS) SQL injection Cross-site request forgery XML external entity injection Directory traversal Server-side request forgery Customers Organizations Testers Developers Company About PortSwigger News Careers Contact Legal Privacy Notice Insights Web Security Academy Blog Research The Daily Swig PortSwigger Logo Follow us (c) 2022 PortSwigger Ltd.